Commit Graph
413 Commits
Author SHA1 Message Date
Nikhil-Ladha 9fea9cd865 multus: add sample job manifest for multus config validation
added a sample job manifest named `multus-validation` that
validates the multus configuration in the cluster.

Signed-off-by: Nikhil-Ladha <nikhilladha1999@gmail.com>
2023-08-11 10:55:29 +05:30
Travis Nielsen 65f413ce1f Merge pull request #12286 from subhamkrai/fix-node-loss-rbd
core: faster recovery from rbd rwo node loss
2023-07-07 10:35:59 -06:00
subhamkrai 39b5c057ce core: faster recovery from rbd rwo node loss
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-07-07 21:16:25 +05:30
Travis Nielsen 18e2502a69 Merge pull request #12295 from subhamkrai/remve-default-scc
security: remove default scc privileges
2023-07-07 08:24:37 -06:00
subhamkrai 48f84b37e8 security: drop all capabilities to the container
adding drop `ALL` capabilities in rook operator container
as this is not required and will remove warning in ocp cluster.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-07-07 17:06:48 +05:30
Travis Nielsen 854bc7d980 Merge pull request #12143 from parth-gr/IPV6-external
external: add support for IPV6 ceph daemons
2023-07-06 15:39:05 -06:00
Rakshith R aa0aa34c23 csi: update csi sidecars' image version
Signed-off-by: Rakshith R <rar@redhat.com>
2023-07-06 16:18:35 +05:30
parth-gr de61187eb4 external: add support for IPV6 ceph daemons
updated some function which were strictly used for IPV4

Signed-off-by: parth-gr <paarora@redhat.com>
2023-07-05 17:13:06 +05:30
mysiki b5d0d80444 external: fix import-external-cluster.sh and documentation
fix import-external-cluster.sh in order to work with set -e bash directive, see issue https://github.com/rook/rook/issues/12412
fix documentation mispell in namespace word

Closes: https://github.com/rook/rook/issues/12412

Signed-off-by: mysiki <hoaxboy@wanadoo.fr>
2023-07-05 13:01:44 +02:00
Blaine Gardner d6475408d9 Merge pull request #12437 from sudharsanomprakash/patch-1
Multus Validation : Added verbs "deletecollection"
2023-06-29 09:46:27 -06:00
Travis Nielsen 58994fe922 Merge pull request #12418 from Jeansen/update_docu
Remove deprecated annotation
2023-06-29 08:38:25 -06:00
Sud 2547372527 multus: add deletecollection capability for validation tool
Without deletecollection capability the image pullers won't be deleted, causing multus validation to fail.
    Added deletecollection verbs to the daemonsets resource in role rook-ceph-system
    This is fix for Issue: https://github.com/rook/rook/issues/12435

    Signed-off-by: Sudharsan Omprakash <sudharsan.omprakash@yahoo.com>
2023-06-28 17:45:18 -04:00
Travis Nielsen c2517f47d0 Merge pull request #12417 from parth-gr/idempotent-external
external: make import script idempotent
2023-06-28 14:31:11 -06:00
Rakshith R fa1be14bca csi: update csiaddons k8s-sidecar to v0.7.0
This commit updates k8s-sidecar to v0.7.0
and all links now point to v0.7.0 tag.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-06-28 20:38:29 +05:30
Rakshith R 1af70aca60 csi: update cephcsi to v3.9.0
This commit updates cephcsi image to
v3.9.0 release and also removes support
for v3.7.x.

refer:
https://github.com/ceph/ceph-csi/releases/tag/v3.8.0

Signed-off-by: Rakshith R <rar@redhat.com>
2023-06-28 20:38:29 +05:30
parth-gr 483c432b26 external: make import script idempotent
import script may be need a re-run if other
resources need to be configured
for ex: if rbd is configured and later on point
someone want to also configure rgw, it will have
a choice

Closes: https://github.com/rook/rook/issues/12412

Signed-off-by: parth-gr <paarora@redhat.com>
2023-06-28 19:09:42 +05:30
subhamkrai a2e3d30526 security: remove default scc privileges
with `requiredDropCapabilities: ["All"]` we can
drop all the default privileges and we can add the
privileges required `allowedCapabilities:` here.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-06-28 15:14:41 +05:30
Marcel Lautenbach 9d335ad814 docs: replace deprecated ingress.class annotation
Documentation and examples used a deprecated annotation to set the Ingress class name. This commit replaces it with the correct version using spec.ingressClassName .

Signed-off-by: Marcel Lautenbach <mlautenb@gmail.com>
2023-06-23 19:31:54 +02:00
travisn 557a3e06cc core: api updates for controller runtime v0.15
For the controller runtime v0.15 there are some breaking
changes to the api that need to be updated.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-06-22 10:33:28 -06:00
travisn 11d83bfbec pool: add .mgr pool to the stretch cluster examples
The stretch clusters must create pools with a pool spec
that is valid for the stretch scenario, with 4 replicas
and failure domain and sub failure domain as needed
to match the topology. Otherwise, ceph will create a
default .mgr pool which will have replica 3 which is
invalid for the stretch scenario.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-06-12 12:28:10 -06:00
Sachin Prabhu 8705f2b37e nfs: set correct kerberos domain in /etc/idmapd.conf
We add a new field domainName to the Kerberos section. The field is used
to setup /etc/idmapd.conf with the domain name. This allows idmapper to
map to kerberos credential to the correct uid/gid.

We add Spec.Security.Kerberos.DomainName to the CRD

Signed-off-by: Sachin Prabhu <sprabhu@redhat.com>
2023-06-09 18:06:45 +01:00
Redouane Kachach 08754f6197 mgr: removing unnecessary rook-ceph-mgr rbac entries
These rbac changes were introduced as part of #11845 PR to enable
sidecar accessing mgr pods but in fact they are not necessary
as rook-ceph-mgr role had already the ability to update pods

Closes: https://github.com/rook/rook/issues/12336

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-06-06 22:12:23 +02:00
Travis Nielsen f6da90d539 Merge pull request #12264 from parth-gr/rgw-external-tls
external: fqdn should be persisted
2023-05-31 14:00:59 -06:00
parth-gr f66de7b9df external: fqdn should be persisted
1) donot change rgw fqdn to ip if provided,
As now the bucket class supports the
entry of fqdn

2) update crds with new description in EndpointAddress

Signed-off-by: parth-gr <paarora@redhat.com>
2023-05-31 17:36:29 +05:30
Travis Nielsen 6417ed4047 Merge pull request #12256 from thotz/add-missing-caps-object-user
object: add missing caps for object store user
2023-05-30 16:37:18 -06:00
Alexander Trost 178c916012 helm: add exporter resource entry to ceph cluster
This adds the new `exporter:` resource key to the Ceph cluster example
yaml. It also set some sane resource requests and limits for it in the
CephCluster section of the rook-ceph Helm chart.

Closes #11914

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2023-05-30 17:54:49 +02:00
Jiffin Tony Thottan ad0c000e6a object: add missing caps for object store user
Lot of new caps added to rgw users, reflecting same changes on the
object store user CRD.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-05-26 17:36:00 +05:30
travisn 754f073aa5 monitoring: service monitor should not use mgr_role label
The service monitor selectors need to match the mgr service labels.
Since the mgr service labels don't use the mgr_role (only the mgr
service selectors use the mgr_role), the mgr_role should be removed
from the service monitor.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-05-22 14:20:19 -06:00
parth-gr ec2681f82b external: fix rgw check if no multisite flag is passed
if there is no multisite config pass, it will still checks for
the zones and zones group and not able to query anything

Signed-off-by: parth-gr <paarora@redhat.com>
2023-05-16 20:10:29 +05:30
Travis Nielsen 27504b0a25 Merge pull request #12190 from parth-gr/doc-update-rulenamespace
docs: update ruleNamesapce to rulesNamespaceOverride
2023-05-11 11:02:22 -06:00
parth-gr 060bd00281 docs: update ruleNamesapce to rulesNamespaceOverride
there were some places where rulenamesapce was present updated to rulesNamespaceOverride

Closes: rook#12163
Signed-off-by: parth-gr <paarora@redhat.com>
2023-05-11 17:26:04 +05:30
travisn 92a0ab37e3 monitoring: configurable option to disable prometheus metrics
The prometheus mgr module and ceph exporter can now be optionally
disabled by the monitoring.metricsDisabled setting in the
CephCluster CR. These will not be disabled by default, rather
than the mgr module being disabled by default from v1.11.4.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-05-05 16:04:51 -06:00
parth-grandSergio Pérez Fernández c50c308abe external: fix rgw multisite config check
the check validate_rgw_multisite was always checking for realm
updated it to check the specific config

fixed validate_rgw_endpoint pool validation

added missing realm zonegroup and zone while interacting with user resources

Co-authored-by: Sergio Pérez Fernández <sergioperez794@gmail.com>
Signed-off-by: parth-gr <paarora@redhat.com>
2023-05-05 00:56:18 +05:30
Blaine Gardner 6500c11d57 nfs: pare down config file volume sources
Pare down the available volume sources for NFS config files so that the
CRD isn't unnecessarily huge. This allows us to recommend
`kubectl apply` again in the upgrade doc.

Size of the NFS CRD is reduced by approximately 60%.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2023-05-02 11:34:24 -06:00
subhamkrai ad068d966a core: update k8s module to lastet version
updating k8s dependencies like clien-go and
others to v0.26.4

Signed-off-by: subhamkrai <srai@redhat.com>
2023-05-02 22:06:21 +05:30
Travis Nielsen 46e6b7366a Merge pull request #12132 from parth-gr/dotpool-update
external: check for pool and cluster name is provided
2023-04-25 08:02:14 -06:00
parth-gr e02942ab77 external: check for pool and cluster name is provided
While adding the support for dot and special rbd pools
the check for pool and cluster name check was removed,
Adding it back as it is needed
https://github.com/rook/rook/pull/12056

Signed-off-by: parth-gr <paarora@redhat.com>
2023-04-25 18:48:27 +05:30
travisn db04b127b0 core: remove obsolete journal size config value
The journal size was only applicable to the filestore OSD
format which has not been supported by rook since v1.2.
Remove the remaining obsolete setting from the examples and
code.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-04-24 15:54:53 -06:00
Travis Nielsen eaf3e3662d Merge pull request #12037 from parth-gr/external-multisite-zone
external: add support for multisite in external cluster script
2023-04-13 07:55:44 -06:00
Travis Nielsen 6103cb93dd Merge pull request #12061 from neoaggelos/feat/external
external: do not enforce need for monitoring endpoint
2023-04-12 16:08:54 -06:00
Angelos Kolaitis 9e4a6ddee5 external: do not enforce need for monitoring endpoint
Add --skip-monitoring-endpoint to create-external-cluster-resources.py
to allow the script to work with Ceph clusters without an enabled
prometheus module.

Document the new flag in external-cluster.md and add relevant unit tests

Signed-off-by: Angelos Kolaitis <neoaggelos@gmail.com>
2023-04-12 21:04:48 +03:00
Travis Nielsen 9e55bbcc7c Merge pull request #12056 from parth-gr/external-restricted-dotpool
external: add alias rbd pool name to support . pools name
2023-04-12 09:42:52 -06:00
parth-gr 6c3dabcf5f external: add alias rbd pool name to support . pools name
if restricted permission was on the . was appended to k8s secret and
failed to create the secret so added a alias name is user wan't to suuport
pool with . in name

Signed-off-by: parth-gr <paarora@redhat.com>
2023-04-12 19:26:20 +05:30
travisn 609ac91cb1 core: update default image to ceph v17.2.6
With the release of ceph v17.2.6, the examples and the base
image for the operator are updated to pick up the latest
and greatest.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-04-11 14:07:11 -06:00
sp98 aefe0054c4 core: add clusterID to MCS spec
ClusterID uniquely identifies a cluster. It is used as a prefix to
nslookup exported services.
For example: <clusterid>.<svc>.<ns>.svc.clusterset.local

Signed-off-by: sp98 <sapillai@redhat.com>
2023-04-11 15:17:21 +05:30
parth-gr b60da0b8c1 external: add support for multisite in external cluster
Add support for realm, zone and zonegroup

Signed-off-by: parth-gr <paarora@redhat.com>
2023-04-10 20:03:16 +05:30
Mathieu Parent 1578d55b4d helm: drop snapshot.storage.k8s.io/v1beta1
v1 exists since k8s v1.20

Signed-off-by: Mathieu Parent <mathieu.parent@insee.fr>
2023-04-08 21:18:35 +02:00
Travis Nielsen 36138fcebe Merge pull request #12028 from parth-gr/external-enforce
external: do not enforce rbd, cephfs and rgw flags for the external cluster
2023-04-06 08:52:44 -06:00
parth-gr 626d1c44ff external: name correction of validate_rgw_metadata_ec_pool_name function
The function is used for rbd so it should be name to validate_rbd_metadata_ec_pool_name

Signed-off-by: parth-gr <paarora@redhat.com>
2023-04-05 20:54:13 +05:30
parth-gr e734911532 external: do not enforce rbd, cephfs and rgw flags for the external cluster
there might be a user who only wants to use rbd, so don't enforce them
to to create all the pools and pass the flags

Closes: https://github.com/rook/rook/issues/11846
Signed-off-by: parth-gr <paarora@redhat.com>
2023-04-05 17:21:04 +05:30